Vulnerability response based on interface instrumentation
Abstract
A computer-implemented method for protecting a software code against a security vulnerability, wherein the software code comprises at least one software code component, some of which comprising a function call, whereby each function call represents a dependency is disclosed. The method comprises integrating a dependency profiler with the at least one software code component, intercepting, at runtime of the software code component, the function call to at least one API of the service component, thereby detecting dynamically dependencies, recording a sequence of usage of the detected dependencies in a profiler report, and performing a response action based on known vulnerabilities in the sequence of the usage of the detected dependencies
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method for protecting a software code against a security vulnerability, wherein the software code comprises at least one software code component, some of which comprising a function call to a service component, whereby each function call represents a dependency, the method comprising:
integrating a dependency profiler with the at least one software code component; intercepting, at runtime of the software code component, the function call to at least one API of the service component, thereby detecting dynamically dependencies; recording a sequence of usage of the detected dependencies in a profiler report; and performing a response action based on known vulnerabilities in the sequence of the usage of the detected dependencies.
2 . The method according to claim 1 , further comprising:
performing the response action if the scoring value of the dependency is larger than a predefined threshold value.
3 . The method according to claim 2 , wherein the performing of the response action comprises:
determining a reaction type dependent on the scoring value of a predefined sequence of dependencies.
4 . The method according to claim 1 , further comprising:
retrieving information about known vulnerabilities including information about dangerous sequences of dependencies having a potential for causing a security issue with the service component.
5 . The method according to claim 1 , further comprising:
retrieving information about known vulnerabilities including information about dangerous function call parameter values, each of which being indicative of a potential security issue with the service component.
6 . The method according to claim 1 , further comprising:
marking a service component relating to the dependency as to be updated depending on the reaction type.
7 . The method according to claim 1 , wherein the integrating a dependency profiler with the at least one software code component further comprises:
generating the wrapper code for a called library dynamically.
8 . The method according to claim 1 , wherein the reaction type comprises at least one from the group consisting of:
generating an alert; blocking an API specific functionality of the software code component; blocking the function call to the service component; terminating an execution of the software code component; marking the dependent component as “to be updated”; changing function call parameters, thereby circumventing a vulnerability; and changing a function call sequence, thereby circumventing a vulnerability.
9 . The method according to claim 1 , wherein the dependency profiler changes function call arguments for the function call to the service component based on values of the function call arguments being known to be vulnerable for the software code.
10 . The method according to claim 1 , wherein the profile wrapper changes the sequence of function calls to the service component based on specific sequences of function calls being known to be vulnerable for the software code.
11 . The method according to claim 8 , further comprising:
allow-listing a function call in case a vulnerability for values of the function call arguments are known.
12 . A runtime dependency security computer system for protecting a software code against a security vulnerability, the system comprising:
one or more processors and a memory operatively coupled to the one or more processors, wherein the memory stores program code portions which, when executed by the one or more processors, enable the one or more processors to:
integrate a dependency profiler with the at least one software code component;
intercept, at runtime of the software code component, the function call to at least one API of the service component, thereby detecting dynamically dependencies;
record a sequence of usage of the detected dependencies in a profiler report; and
perform a response action based on known vulnerabilities in the sequence of the usage of the detected dependencies.
13 . The computer system according to claim 12 , wherein the processor performs the response action based on the scoring of the dependency being larger than a predefined threshold value.
14 . The computer system according to claim 12 , wherein the processor performs the response action:
determine a reaction type depending on the scoring value of a predefined sequence of dependencies.
15 . The computer system according to claim 12 , wherein the processor:
retrieves information about known vulnerabilities including information about dangerous sequences of dependencies having a potential for causing a security issue with the service component.
16 . The computer system according to claim 12 , wherein the processor marks a service component relating to the dependency as to be updated depending on the reaction type.
17 . The computer system according to claim 12 , wherein the processor, when integrating a dependency profiler with the at least one software code component, generates the wrapper code for a called library dynamically.
18 . The computer system according to claim 12 , wherein the reaction type comprises at least one from the group consisting of:
generating an alert; blocking an API specific functionality of the software code component; blocking the function call to the service component; terminating an execution of the software code component; marking the dependent component as “to be updated”; changing function call parameters, thereby circumventing a vulnerability; and changing a function call sequence, thereby circumventing a vulnerability.
19 . The computer system according to claim 12 , wherein the processor is also enabled to:
allow-list a function call in case a vulnerability for values of the function call arguments are known.
20 . A computer program product for securing a software code against a security vulnerability, wherein the software code comprises at least one software code component, some of which comprising a function call to a service component, whereby each function call represents a dependency:
the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions being executable by one or more computing systems or controllers to cause the one or more computing systems to:
integrate a dependency profiler with the at least one software code component;
intercept, at runtime of the software code component, the function call to at least one API of the service component, thereby detecting dynamically dependencies;
record a sequence of usage of the detected dependencies in a profiler report; and
perform a response action based on known vulnerabilities in the sequence of the usage of the detected dependencies.Join the waitlist — get patent alerts
Track US2025165613A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.